Source · Select Committees · Public Accounts Committee
Recommendation 22
22
Previous departmental self-assessments significantly over-estimated actual cyber resilience levels.
Conclusion
The Cabinet Office told us that cyber resilience was substantially lower than it had expected following departments’ previous self–assessments. It had found that the organisations that GovAssure’s independent reviewers had scored poorly were the most over–optimistic in their self–assessments.46 We challenged the Cabinet Office on why it had not introduced GovAssure sooner. The Cabinet Office acknowledged that it had probably been unrealistic to rely on self–assessment and that it had not been sufficiently alert to the threat, until incidents brought it to life.47
Government Response
A response document is linked to this report, dated 18 September 2025. Response attribution to this conclusion has not been verified. Read the response document ↗